Our Support
for Your Business

Our Support Options

TECHNICAL SUPPORT

A healthy deployment. Protection under continuous care.

We keep your WanGuard deployment technically healthy and help adapt it to changing load. In SILVER your team runs the protection configuration. From GOLD we also review the configuration regularly and implement agreed corrections, to reduce the risk of an ineffective response and of unnecessary blocking.

Support tiers and the tasks each one covers
Support tasks SILVEREntry GOLDSystem care GOLD +Weekends & holidays PLATINUMFull handover
Support availability Business daysMon–Fri Business daysMon–Fri 7 days a weekweekends and holidays too 7 days a weekweekends and holidays too
Response to a request Next business day Same business day Same day Same day
Help with WanGuard and Linux operation, plus updates We answer questions about operating and running the deployment. We carry out updates twice a year and critical (CVE) updates, with changes agreed beforehand. We remind you of important dates, including the end of the WanGuard licence and of technical support. ✓ ✓ ✓ ✓
Threshold recommendations, backups and help with false positives We help choose detection settings and identify the causes of unwanted alarms. We maintain system backups. In SILVER, applying recommendations to the protection configuration stays with your team; from GOLD we carry out the agreed corrections. ✓ ✓ ✓ ✓
Process monitoring and automatic recovery of sensors and filters We monitor the state of WanGuard processes. In the cases covered by the mechanisms in place, sensors and filters are restored automatically. Problems that require an engineer are handled within the package you choose. ✓ ✓ ✓ ✓
Deployment supervision and tuning, more than 400 parameters We monitor more than 400 parameters of the deployment components: CPU, memory, disks, network cards, databases, BGP, DPDK and Flow and SNMP sensors, depending on the configuration. We react to problems we find and tune resources and databases to the load. This helps keep the deployment healthy also when the number of anomalies grows during attacks. ✓ ✓ ✓ ✓
Event analysis and detection tuning We analyse recorded anomalies and attacks together with how the protection rules behaved, and prepare corrections that improve detection and reduce false positives. In GOLD and GOLD+ the day-to-day watching of alarms stays with your team; the scope of incident handling is set out in the offer. ✕ ✓ ✓ ✓
Technical consultations and configuration review In Zoom sessions we go through anomalies, detection thresholds, planned changes and questions from your administrators. We agree how protection should behave, taking into account the role of each subnet and service. ✕ ✓ ✓ ✓
ITORO implements the agreed protection changes We prepare and implement agreed thresholds, list assignments and WanGuard response settings, once you approve them, and we check the effect. Your administrator receives a summary of the work done instead of translating a multi-page audit into console settings. ✕ ✓ ✓ ✓
We find gaps and errors in the protection configuration Our program checks the whole configuration under audit: prefixes defined in WanGuard, list assignments, required decoders, units and threshold values, and response settings. We point out which corrections to make first and carry them out as part of the agreed work. Once the deployment is prepared, reviews run every two weeks. We also check the effect of the changes. ✕ ✓ ✓ ✓
Traffic profiling tailored to your network We use traffic history stored in ClickHouse and the profiling capabilities of WanGuard 9.0. ITORO configures and tunes profiles for IP addresses and subnets, taking account of their purpose and normal traffic patterns. We define acceptable deviations, minimum trigger levels and the response: notification or activation of protection. These profiles complement threshold lists and help detect events that may remain below fixed thresholds. We introduce changes in stages and check their impact on legitimate traffic. ✕ ✓ ✓ ✓
We show the board the scale of threats and the state of protection We present the number and scale of confirmed attacks, the periods of highest activity and an assessment of how protection performed, based on the data available. The board gets an understandable summary of the situation in the network. The cadence of these summaries is agreed with you. ✕ ✓ ✓ ✓
We point out the threats an administrator should deal with first We passively analyse available external data on open services, vulnerable versions and reported threats, and combine it with WanGuard events. Your administrator receives ordered recommendations with an urgency rating, in particular for hosts that show both vulnerability signals and attack activity. Changes outside WanGuard stay with you unless agreed otherwise. ✕ ✓ ✓ ✓
We take over WanGuard administration We administer the deployment and watch alarms day to day, within the agreed scope and service hours. You tell us about changes in the network and service needs, and ITORO prepares and carries out the agreed work. Your team does not have to operate the WanGuard console day to day. ✕ ✕ ✕ ✓
Scope of care 4 of 12 items 11 of 12 items 11 of 12 items 12 of 12 items
Pricing €350 /month annually in advance €3,850
12 months for the price of 11
€1,500 /month annually in advance €16,500
12 months for the price of 11
€1,800 /month annually in advance €19,800
12 months for the price of 11
€4,000 /month annually in advance €44,000
12 months for the price of 11
Choose the work you want to hand over to ITORO

The choice comes down to how much of the day-to-day work stays with your team and how much ITORO takes over.

scope covered by ITOROstays with the client team
SILVER ITORO keeps the deployment technically healthy; your team runs the protection configuration and watches the alarms.
GOLD In addition, we take over regular review of the configuration and implementation of the agreed corrections.
GOLD + The GOLD scope with support also at weekends and on public holidays.
PLATINUM We take over administration and the day-to-day watching of alarms during service hours.
Package scope and the number of protected networks. Standard packages cover care of the client network. If protection is to cover multiple networks or multiple entities, for example where an operator provides protection to its own customers, the workload grows with the number and nature of the protected networks and requires assessment in each case. In such cases we prepare an individual quotation.
Emergency support

Under attack? 24/7 rapid response

When an attack is live, minutes matter. Our emergency package gives you a direct line to ITORO engineers and a defined escalation path, day or night.

  • 24/7 contact for active DDoS incidents
  • Protection online in as little as 2 hours when your server & router are prepared (RTBH / BGP FlowSpec)
  • Hands-on tuning of WanGuard, FlowSpec and RTBH during the attack
  • Priority handling for GOLD / PLATINUM customers
Get emergency help
Reporting

Reports when you need them

We don't flood you with paperwork after every event. When an incident must be reported to a regulator or government agency, ITORO prepares the documentation on request, with the exact scope, depth and format agreed in advance with sales so it meets your country's and agency's requirements.

  • Attack timeline: start, peak, vectors and duration
  • Traffic evidence and volumetric graphs (pps / bps)
  • What was mitigated, how, and the impact avoided
  • Regulatory summaries (e.g. NIS2) tuned to your jurisdiction, provided under the emergency package
  • Recommendations to harden against the next attack
Compliance · EU NIS2 Directive (2022/2555)

DDoS resilience is now a legal obligation

NIS2 makes DDoS protection and incident reporting mandatory for ISPs, telecoms and digital infrastructure across the EU. Here is what the directive asks for, and how ITORO covers it.

Article 21

Technical & organizational measures

Operators must take appropriate, proportionate measures to manage risks to their networks, including protection against availability attacks such as DDoS.

How ITORO covers it: WanGuard detection paired with Juniper MX line-rate filtering, BGP FlowSpec and RTBH: tuned to your network so attacks are stopped, not just observed.

Article 23: 24h / 72h / 1 month

Incident reporting

Significant incidents must be reported to the national CSIRT within 24 hours (early warning), 72 hours (assessment) and one month (final report).

How ITORO covers it: We prepare the attack timelines, traffic evidence and post-incident reports you need to meet those deadlines: see the reports section below.

Governance

Management accountability

Senior management is directly accountable for cybersecurity risk management and can be held liable for non-compliance.

How ITORO covers it: Documented, tested DDoS protection and a clear 24/7 escalation path give management defensible evidence of due diligence.

Essential & important entities

Broad scope & real penalties

NIS2 covers ISPs, telecoms, cloud, data centers and digital infrastructure. Fines reach up to €10M or 2% of global annual turnover.

How ITORO covers it: ITORO gets you compliant on the resilience side before it is tested, as an Andrisoft Gold Partner with network practice going back to 2005.

Is Your Business Safe from DDoS attacks?

DDoS attacks can strike at any time. Don't wait, be proactive in your defense.

See Plans & Pricing